Vehicles, tools and data · Cyber liability
Cyber insurance
Pays the costs of a data breach or cyberattack: investigation, notifying customers, restoring systems, lost income, and claims from people whose data was exposed.
- Who it's for
- Any business that stores customer data, takes payments, or can't operate without its computers.
- Is it required?
- No, but some clients and contracts require it.
Covered and not covered
Usually covered
- Forensic investigation and legal advice after a breach
- Notifying affected customers and credit monitoring
- Ransomware response and restoring data
- Lost income while systems are down
- Lawsuits and some regulatory fines from exposed data
Usually not covered
- Money sent to a scammer after a fake invoice or email, unless you added social engineering coverage
- Improving your security after an attack
- Losses from known, unfixed security problems
- Damage to physical equipment
Real-life examples
Ransomware locks your systems for a week.
Usually coveredPays experts to respond and restore, lost income during the outage, and in many policies, a ransom payment where lawful.
Your bookkeeper wires $40,000 to a fake supplier after a convincing email.
It dependsOnly covered if you added social engineering (or funds transfer fraud) coverage, often with a low limit.
Check your own policy
Find these on your policy or declarations page, or ask your agent:
- Social engineering coverage and its limit
- Security requirements like multi-factor authentication
- A 24/7 breach hotline
- Business interruption waiting period
Not sure where to look? See how to read your policy.